|
Key
|
Name
|
Value
|
Times
|
| HKLM\SOFTWARE\Microsoft\CTF\SystemShared\
|
CUAS |
0
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
|
Taskman |
C:\Documents and Settings\Administrator\knyxi.exe
|
158 |
| HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
|
CriticalSectionTimeout |
2592000
|
1 |
| HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters
|
Transports |
0x5400630070006900700000004e0065007400420049004f00530000000000
|
2 |
| HKLM\SYSTEM\Setup
|
SystemSetupInProgress |
0
|
1 |
| HKLM\SYSTEM\WPA\MediaCenter
|
Installed |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
aFormatTagCache |
0x01000000100000000204000014000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
aFormatTagCache |
0x01000000100000001100000014000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
aFormatTagCache |
0x0100000010000000550000001e000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
aFormatTagCache |
0x01000000100000000200000032000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
aFormatTagCache |
0x01000000120000006001000016000000610100001c000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
cFormatTags |
3
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
aFormatTagCache |
0x010000001000000006000000120000000700000012000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
cFormatTags |
3
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
aFormatTagCache |
0x0100000010000000420000001c000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
aFormatTagCache |
0x01000000100000003100000014000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
aFormatTagCache |
0x01000000100000003001000016000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
aFormatTagCache |
0x01000000100000002200000032000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
midimapper |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.iac2 |
C:\WINDOWS\system32\iac25_32.ax
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.imaadpcm |
imaadp32.acm
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.l3acm |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msadpcm |
msadp32.acm
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msaudio1 |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msg711 |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msg723 |
msg723.acm
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msgsm610 |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.sl_anet |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.trspch |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.I420 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.M261 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.M263 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.cvid |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv31 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv32 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv41 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv50 |
|
1 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iyuv |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.mrle |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.msvc |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.uyvy |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.yuy2 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.yvu9 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.yvyu |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
wavemapper |
|
2 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
TransparentEnabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName
|
ComputerName |
PC
|
1 |
| HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm
|
wheel |
1
|
1 |
| HKLM\System\CurrentControlSet\Control\ProductOptions
|
ProductType |
WinNT
|
1 |
| HKLM\System\CurrentControlSet\Services\LDAP
|
LdapClientIntegrity |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Domain |
|
6 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Hostname |
pc
|
6 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
UseDomainNameDevolution |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
HelperDllName |
%SystemRoot%\System32\wshtcpip.dll
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
Mapping |
0x0b0000000300000002000000010000000600000002000000010000000000
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MaxSockaddrLength |
16
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MinSockaddrLength |
16
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
UseDelayedAcceptance |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters
|
WinSock_Registry_Version |
2.0
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Num_Catalog_Entries |
3
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Serial_Access_Num |
4
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
DisplayString |
Tcpip
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
ProviderId |
0x409d05229e7ecf11ae5a00aa00a7112b
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
SupportedNameSpace |
12
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
DisplayString |
NTDS
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
LibraryPath |
%SystemRoot%\System32\winrnr.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
ProviderId |
0xee37263b80e5cf11a55500c04fd8d4ac
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
SupportedNameSpace |
32
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
DisplayString |
Network Location Awareness (NLA) Namespace
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
ProviderId |
0x3a244266a83ba64abaa52e0bd71fdd83
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
SupportedNameSpace |
15
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Next_Catalog_Entry_ID |
1020
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Num_Catalog_Entries |
13
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Serial_Access_Num |
6
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\Setup
|
SystemSetupInProgress |
0
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle
|
Language Hotkey |
1
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle
|
Layout Hotkey |
2
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Multimedia\Audio
|
SystemFormats |
CD Quality,Radio Quality,Telephone Quality
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Local Settings |
%USERPROFILE%\Local Settings
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Personal |
%USERPROFILE%\My Documents
|
1 |